The original title is "Chinese spyware code was copied from America's NSA" - no spies that hijack, they just used code that was out in the open.
The article mentions the real problem: Whenever alphabet agencies detect a backdoor into widely used software or devices, they can decide if they add the hack to their arsenal, or if they alert the manufacturer. Whenever they decide to keep a backdoor secret, it can also used by an adversary. Be it that others detect the backdoor too, or be it that the information gets leaked.
There are many backdoors and zero days, teams that work hard to find new ones, there are spies and hackers, and there are markets for zero days. The rest is speculation. No professional actor will leave traces of the origin of their work, using VPN, fake timezones and comments in different languages instead. Maybe the Chinese bought some stuff, maybe it was North Korea acting as Chinese, maybe the CIA using Ukrainians to steal secrets they can sell to the Russians. We will never know.
(post is archived)